nerdexam
(ISC)2

CISSP · Question #782

An organization's data policy MUST include a data retention period which is based on

The correct answer is D. regulatory compliance.. An organization's data policy must include a data retention period that is based on regulatory compliance. Regulatory compliance is the adherence to the laws, regulations, and standards that apply to the organization's industry, sector, or jurisdiction. Regulatory compliance may

Submitted by jian89· Mar 5, 2026Security and Risk Management

Question

An organization's data policy MUST include a data retention period which is based on

Options

  • Aapplication dismissal.
  • Bbusiness procedures.
  • Cdigital certificates expiration.
  • Dregulatory compliance.

How the community answered

(17 responses)
  • B
    6% (1)
  • D
    94% (16)

Explanation

An organization's data policy must include a data retention period that is based on regulatory compliance. Regulatory compliance is the adherence to the laws, regulations, and standards that apply to the organization's industry, sector, or jurisdiction. Regulatory compliance may dictate how long the organization must retain certain types of data, such as financial records, health records, or tax records, and how the data must be stored, protected, and disposed of. The organization must follow the regulatory compliance requirements for data retention to avoid legal liabilities, fines, or sanctions.

Topics

#data retention#regulatory compliance#data policy#legal requirements

Community Discussion

No community discussion yet for this question.

Full CISSP Practice